Student Reviews
( 5 Of 5 )
1 review
Video of XML External Entity Injection TryHackMe Advent of Cyber Day 5 Walkthrough in Web PenTesting course by Motasem Hamdan channel, video No. 118 free certified online
The video provides a detailed walkthrough of Day 5 of the Advent of Cyber 2024 challenge on the TryHackMe platform. This challenge focuses on understanding XML (Extensible Markup Language) and XML External Entity (XXE) Injection vulnerabilities.
Receive Cyber Security Field, Certifications Notes and Special Training Videos
https://buymeacoffee.com/notescatalog/membership
TryHackMe Advent of Cyber Day 2024 Full Walkthrough
https://motasem-notes.net/tryhackme-advent-of-cyber-2024-full-walkthrough/
Store
https://buymeacoffee.com/notescatalog/extras
Patreon
https://www.patreon.com/motasemhamdan
Instagram
https://www.instagram.com/mastermindstudynotes/
Google Profile
https://maps.app.goo.gl/eLotQQb7Dm6aiL8z6
LinkedIn
[1]: https://www.linkedin.com/in/motasem-hamdan-7673289b/
[2]: https://www.linkedin.com/in/motasem-eldad-ha-bb42481b2/
Instagram
https://www.instagram.com/mastermindstudynotes/
Twitter
https://twitter.com/ManMotasem
Facebook
https://www.facebook.com/motasemhamdantty/
00:00 Introduction to Advent of Cyber 2024
00:09 Overview of Day 5 Challenge
00:18 Understanding XML Basics
01:03 Document Type Definitions (DTD) Explained
01:51 Introduction to XML Entities
02:33 XML External Entity (XXE) Attacks
03:27 Deploying the Virtual Machine
04:03 Interacting with the Challenge Website
05:19 Adding Products to Wishlist
06:12 Investigating Wishlist Requests
07:26 Exploring XML in Wishlist Requests
08:28 Exploiting XXE Vulnerabilities
10:09 Accessing Unauthorized Wishes
12:02 Solving the Challenge and Extracting the Flag
13:32 Outro and Next Steps